← Home

@tryghost/ghst

A modern Ghost CMS CLI

18
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

zimoatghostallouiskernalghostchrisraibleerisdsjohnonolankevinansfieldcobbspuraileencgnjlohminimaluminiumsam-lordpauladamdavisbobvaneckjoeegrigghadretjonhickmanerik-ghostsagzyvershwalzach1618mike182ukluissazevedolsingernickmoretonrenatoworksrblstr-ghostevanhahn-ghostaustin.burdineweylandswartghost-slimertmciescojonatan-ghost9larsons

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publishing on official TryGhost package; legitimate. ai
dependencies unvetted-dep:@jq-tools/jq AI (dependencies): Small utility dep, no fetch/exec behavior, low risk. ai
publish-pattern new-deps-added AI (publish-pattern): Single benign jq wrapper added, not a supply-chain pattern match. ai
maintainer-change maintainer-added AI (maintainer-change): TryGhost org package published via GitHub Actions with SLSA provenance; maintainer additions are expected for an active org project. ai
dependencies unvetted-dep:gscan AI (dependencies): gscan is the official Ghost theme validator, a well-known TryGhost ecosystem package. ai
dependencies unvetted-dep:markdown-it AI (dependencies): markdown-it is a widely-used, well-maintained markdown parser with no malicious indicators. ai
phantom-deps phantom-dep:@tryghost/mg-json AI (phantom-deps): Same-org migration utility; used in CLI sub-commands, stable false positive. ai
phantom-deps phantom-dep:@tryghost/mg-wp-xml AI (phantom-deps): Same-org migration utility; used in CLI sub-commands, stable false positive. ai
typosquat typosquat.levenshtein:jest AI (typosquat): @tryghost/ghst is 'Ghost' abbreviated under the official TryGhost org scope; not a typo of jest. ai
phantom-deps phantom-dep:@tryghost/mg-medium-export AI (phantom-deps): Same-org migration utility; used in CLI sub-commands, stable false positive. ai
phantom-deps phantom-dep:@tryghost/mg-substack AI (phantom-deps): Same-org migration utility; used in CLI sub-commands, stable false positive. ai
typosquat typosquat.levenshtein:got AI (typosquat): @tryghost/ghst is 'Ghost' abbreviated under the official TryGhost org scope; not a typo of got. ai
phantom-deps phantom-dep:ink AI (phantom-deps): CLI tool using ink/react for terminal UI; may be used indirectly via dynamic imports or sub-commands. ai
phantom-deps phantom-dep:ora AI (phantom-deps): CLI spinner library; likely used in sub-commands or dynamically loaded CLI features. ai
phantom-deps phantom-dep:conf AI (phantom-deps): Config persistence library for CLI; may be used indirectly in sub-commands. ai
phantom-deps phantom-dep:react AI (phantom-deps): Required peer dep for ink terminal UI framework; stable false positive for this CLI package. ai

Versions (showing 18 of 18)

Version Deps Published
0.16.2 19 / 10
0.16.0 19 / 10
0.15.3 18 / 9
0.15.2 18 / 9
0.15.1 18 / 9
0.15.0 18 / 9
0.14.1 18 / 9
0.14.0 18 / 9
0.13.0 18 / 9
0.11.0 18 / 9
0.10.0 18 / 9
0.8.0 18 / 9
0.7.0 18 / 9
0.5.0 18 / 9
0.4.3 18 / 9
0.4.2 18 / 9
0.4.1 18 / 9
0.4.0 18 / 9

v0.16.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.15.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.15.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.